CVE-2024-23111: Fortinet FortiOS

Medium severity, CVSS 4.8. EPSS: 1% chance of exploitation in the next 30 days.

An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.

Affected products

  • Fortinet FortiOS: from 7.0.0, before 7.0.14 (fixed in 7.0.14); from 7.2.0, before 7.2.8 (fixed in 7.2.8); from 7.4.0, before 7.4.4 (fixed in 7.4.4)
  • Fortinet FortiProxy: from 7.0.0, before 7.0.15 (fixed in 7.0.15); from 7.2.0, before 7.2.9 (fixed in 7.2.9); from 7.4.0, before 7.4.3 (fixed in 7.4.3)

Published 2024-06-11. Last modified 2026-06-17.